Security Scan Report: dkb-helpdesk.justns.ru

Site favicon
Submitted: Dec 12, 2025, 5:31:17 PMCompleted: Dec 12, 2025, 5:31:34 PMpubliccompleted
Loading additional data...

Summary

This website contacted 22 IPs in 4 countries across 6 domains to perform 16 HTTP transactions. The main domain is dkb-helpdesk.justns.ru and was registered NaN years ago.

Submitted URL: https://dkb-helpdesk.justns.ru/dkb_2025/login.php

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed phishing site impersonating DKB, collects user credentials.

Risk Factors
Malicious primary domain indicator (justns.ru)
Credential harvesting form (username/password)
Brand impersonation on a suspicious subdomain
Unranked domain presenting a major financial brand
Domain age information unavailable

Details

Page Title

DKB Banking

Scan Type

public

Language

🇩🇪

German

(50% confidence)

Category

finance banking

(60%)

Domain Information

The domain name 'dkb-helpdesk.justns.ru' uses the Russian country-code top-level domain (.ru), featuring subdomain 'dkb-helpdesk'. The second-level label 'justns' is 6 characters long split between 1 vowel and 5 consonants. Segmentation suggests two words: just, ns. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dkb-helpdesk.justns.ru/dkb_2025/login.php

Page Load Overview

4.63s
Total Load Time
16
HTTP Requests
6
Domains
493 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:50%
Script Type:Latin
Text Length:257 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking60% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
60%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16104.17.25.14United States
AS13335CLOUDFLARENET
0185.22.155.27Russia
AS51659LLC Baxet
0151.101.130.137San Francisco, California, United States
AS54113FASTLY
0104.16.174.226United States
AS13335CLOUDFLARENET
0142.250.186.99United States
AS15169GOOGLE
0142.250.186.106United States
AS15169GOOGLE
02a00:1450:4001:813::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
02a00:1450:4001:829::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
02606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
02a00:b700::1cHong Kong
AS51711iNet Ltd
1622--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F3915310B4F4647B118350B9BDA62A0EBE91D50BC40D890575BC5EDC2FC3EA7CDA3A1E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:5cGe9oNKWf6fjh18QmFVsMIEj6oZjhhtzEfw:SGe9oNKWuPmFOmj6oZjhhtzEfw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4420:AUAxAAUAABBQgIABAUGaCABAAgAAAkQBAAIAEAUxEhECCREHQAECAAJIEEBOMAACAJAgJgBGAEACYgACJIAQkAQAAwLGEAEA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e700ffff
Perceptual Hash:b3e2cc1de6e219c8
Difference Hash:9409284d4c380408
Wavelet Hash:74e4ece4e400f0f0
Color Hash:#2dd269

Scan History

Scan history not available

Unable to load historical scan data